Sr. Director, Governance, Risk & Compliance
$229,500–$310,500 year
HybridCambridge, Massachusetts, United States
Job Summary
Senior Director of Governance, Risk & Compliance (GRC) leads the GRC program for Alnylam’s cybersecurity function, defining and maturing risk management, regulatory compliance, and security governance to align with NIST CSF v2.0, enterprise risk management, and applicable biotech/pharma regulations. Balances strategic leadership with hands-on execution, partnering across business and IT, and reporting to the VP/CISO. The role is hybrid and primarily based in Cambridge, MA, and involves overseeing cyber risk lifecycle, GxP systems alignment, audits, third-party risk management, and executive/board reporting while ensuring compliance with HIPAA, SOX, FDA-adjacent regulations, CSV, privacy requirements, and evolving regulations (e.g., NIS2). Key activities include defining risk-based metrics, maturing the risk program, embedding cybersecurity considerations into system lifecycle and validation, and building a high-performing GRC organization with cross-functional collaboration. Qualifications include 15+ years in cybersecurity/risk/compliance with 10+ years leadership, deep knowledge of NIST CSF/800-53, ISO 27001 and ERM, experience in regulated environments, and relevant certifications (CISSP, CISM, CRISC, CISA preferred). The role demands the ability to translate risk topics for executive audiences and to lead internal/external audits and third-party risk management efforts.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.